29% of the exam — the second-largest domain.
4 sub-topics · this deck covers sub-topic 4 of 4 — the last one in this module
↑ Module 2 OverviewModule 1 covered why Group Push matters. This is the deep dive on how it actually works — the mechanics an exam question will actually probe.
By name — an admin manually selects specific groups to push.
By rule — multiple groups are pushed automatically based on matching criteria in group names or descriptions. Unavailable for Active Directory.
That last point matters: turning on Group Push for an existing app group can silently remove members who were only ever added on the app's side.
Create Group — generates a brand-new group in the target app and links it.
Link Group — connects an Okta group to an existing app group instead.
Once linked, the app-side group no longer appears under Directory > Groups. Admins can optionally auto-rename the app group to match Okta's name, and should run "Refresh App Groups" before linking to pick up any recent changes made directly in the app.
For Microsoft Entra ID groups specifically: you can mark a group as role-assignable during creation — but you cannot change that setting afterward. Get it right the first time.
Watch for scenario questions built around these traps:
→ "A group needs to be pushed to Active Directory using rule-based matching." = not supported — AD only allows push by name.
→ "After enabling Group Push, some app-side members disappeared." = expected — Okta reconciles membership and removes anyone not in the linked Okta group.
→ "A pushed group also needs to be used for direct app assignment." = not possible — mutually exclusive.
Sources: help.okta.com — usgp-about-group-push.htm · usgp-configure-enhanced-group-push.htm
✓ Module 2: Provisioning — complete (4 of 4 sub-topics)